CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: KEV only
1,698 result(s) · page 38 of 85
CVE-2022-26925
KEV MEDIUM

Windows LSA Spoofing Vulnerability

CVSS 5.9 Microsoft windows_10_1507 2022-05-10
CVE-2022-26923
KEV HIGH

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS 8.8 Microsoft windows_10_1507 2022-05-10
CVE-2022-30333
KEV HIGH

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke...

CVSS 7.5 Debian debian_linux 2022-05-09
CVE-2022-1388
KEV CRITICAL

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x ver...

CVSS 9.8 F5 big-ip_access_policy_manager 2022-05-05
CVE-2022-24706
KEV CRITICAL

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has ...

CVSS 9.8 Apache couchdb 2022-04-26
CVE-2022-29499
KEV CRITICAL

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 4...

CVSS 9.8 Mitel mivoice_connect 2022-04-26
CVE-2022-27926
KEV MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute ...

CVSS 6.1 Synacor zimbra_collaboration_suite 2022-04-21
CVE-2022-27925
KEV HIGH

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights h...

CVSS 7.2 Synacor zimbra_collaboration_suite 2022-04-21
CVE-2022-27924
KEV HIGH

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes une...

CVSS 7.5 Synacor zimbra_collaboration_suite 2022-04-21
CVE-2022-21445
KEV CRITICAL

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0...

CVSS 9.8 Oracle application_development_framework 2022-04-19
CVE-2022-29464
KEV CRITICAL

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory travers...

CVSS 9.8 Wso2 api_manager 2022-04-18
CVE-2022-28810
KEV MEDIUM

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script...

CVSS 6.8 Zohocorp manageengine_adselfservice_plus 2022-04-18
CVE-2022-26904
KEV HIGH

Windows User Profile Service Elevation of Privilege Vulnerability

CVSS 7 Microsoft windows_10_1507 2022-04-15
CVE-2022-24521
KEV HIGH

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS 7.8 Microsoft windows_10_1507 2022-04-15
CVE-2022-24816
KEV CRITICAL

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote ...

CVSS 10 Geosolutionsgroup jai-ext 2022-04-13
CVE-2022-22960
KEV HIGH

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor...

CVSS 7.8 Vmware cloud_foundation 2022-04-13
CVE-2022-22954
KEV CRITICAL

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig...

CVSS 9.8 Vmware identity_manager 2022-04-11
CVE-2022-0609
KEV HIGH

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 Google chrome 2022-04-05
CVE-2022-22965
KEV CRITICAL

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run...

CVSS 9.8 Vmware spring_framework 2022-04-01
CVE-2022-22963
KEV CRITICAL

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a r...

CVSS 9.8 Vmware spring_cloud_function 2022-04-01
1… 36 37 38 39 40 …85
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.